{"id":"CVE-2020-11885","details":"WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.","modified":"2026-07-08T20:58:07.784391Z","published":"2020-04-17T20:15:12.097Z","references":[{"type":"ADVISORY","url":"https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0684"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wso2/product-ei","events":[{"introduced":"0"},{"last_affected":"bfdf341ab6dcfccce35c88b8a1567604f07ba8f5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"6.6.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:*"}}],"versions":["v6.6.0-rc3","v6.6.0","v6.6.0-rc2","v6.6.0-rc1","v6.6.0-beta","v6.5.0-rc1","v6.5.0","v6.5.0-m6","v6.5.0-m4","v6.5.0-m3","v6.5.0-m2","v6.5.0-m1","v6.4.0-rc1","v6.4.0","v6.4.0-m8","v6.4.0-m7","v6.4.0-m6","v6.4.0-m5","v6.4.0-m4","v6.4.0-m3","v6.4.0-m2","v6.4.0-m1","v6.3.0-rc2","v6.3.0","v6.3.0-rc1","v6.3.0-m11","v6.3.0-m10","v6.3.0-m9","v6.3.0-m8","v6.3.0-m7","v6.3.0-m6","v6.3.0-m5","v6.3.0-m4","v6.3.0-m3","v6.3.0-m2","v6.3.0-m1","v6.2.0-rc2","v6.2.0","v6.2.0-rc1","v6.1.1-update24","v6.1.1-update23","v6.1.1-update22","v6.1.1-update21","v6.1.1-update20","v6.1.1-update19","v6.1.1-update18","v6.1.1-update17","v6.1.1-update16","v6.1.1-update15","v6.1.1-update14","v6.1.1-update13","v6.1.1-update12","v6.1.1-update11","v6.1.1-update10","v6.1.1-update9","v6.1.1-update8","v6.0.0-m1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11885.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}